Junglewise Threat Intelligence

CVE-2026-35395: LabRedesCefetRJ WeGIA SQL injection in DespachoDAO.php

CVE-2026-35395 · Severity: high · CVSS 8.8 · Published 2026-04-06

Technologies: LabRedesCefetRJ WeGIA. Vendors: LabRedesCefetRJ.

Executive brief

WeGIA is a web-based management system used by charitable institutions to handle resident records, staff data, and financial information. A security flaw allows logged-in users to bypass data protections and run unauthorized database commands. This could lead to the theft of sensitive personal information, such as medical histories and financial records, or the total deletion of the organization's data.

Technical details

A SQL injection vulnerability exists in `dao/memorando/DespachoDAO.php` within WeGIA versions prior to 3.6.9. The root cause is the unconditional use of `extract($_REQUEST)` in `DespachoControle::listarTodos()`, which populates the `$id_memorando` variable without validation. This variable is then directly interpolated into SQL queries in `DespachoDAO::listarTodos()` without using prepared statements or parameter binding. An authenticated attacker with access to the memorando module can exploit this via the `control.php` endpoint to perform unauthorized data extraction (including database schema and records), modification, or deletion. In certain database configurations, this could potentially escalate to remote code execution via file operations.

Affected products

  • LabRedesCefetRJ WeGIA < 3.6.9

Timeline

  • 2026-04-02: advisory: GitHub security advisory published by vendor
  • 2026-04-06: disclosed: CVE published to NVD
  • 2026-04-06: patched: Vulnerability fixed in version 3.6.9

References

Related threats